Domain 3 of 4 · Chapter 3 of 3

AI Security Operations

Unlock the complete study guide + 1,040 practice questions across 16 full exams.

Bundled into the existing CompTIA SecAI+ premium course — no separate purchase.

14-day money-back guarantee — no questions asked.

Included in this chapter:

  • What this page watches, and against what
  • Threat modelling with an assistant
  • The telemetry every practice here assumes
  • Behaviour analysis: the entity, history and peers
  • Making a behaviour risk score actionable
  • The patterns behaviour analysis is built to catch
  • Continuous monitoring: effectiveness and drift
  • Threat hunting with AI assistance
  • Measuring an AI security operations programme
  • Exam-pattern recognition for AI security operations

What each practice compares against

PropertyThreat modellingBehaviour analysis (UEBA)Continuous monitoringThreat hunting
Reference it compares againstA design, against catalogues of attacker techniqueAn entity, against its own history and its peersA running system, against its approved baseline and control expectationsA stated hypothesis, against the evidence in your data
Unit of outputCandidate threats and treatment decisionsA risk score attached to an entityA control-effectiveness or posture findingA detection, a finding, or a documented negative
When it runsAt design time and on every significant changeContinuously, as telemetry arrivesAt a frequency chosen per controlOn a cadence, or as a campaign against one hypothesis
What AI contributesBreadth of enumeration and first-pass wordingProfiling, peer grouping and scoring at scaleCorrelation, prioritisation and status summarisationHypothesis generation, query drafting and clustering
What it cannot tell youWhether the threat is reachable in your environmentWhether the anomaly is harmfulWhether an unmeasured control still worksWhether the adversary is genuinely absent
Characteristic failureA confident list nobody verifiesA confident score with no explanation attachedA green dashboard over stale evidenceAn open-ended trawl with no recorded scope

Decision tree

Alert or incident already open? Yes Detection and response or security automation No System being designed or changed? Yes Threat modelling design vs technique catalogues No A specific hypothesis to test? Yes Threat hunting hypothesis vs your evidence No Subject: an entity's activity, or the system's posture? Entity Behaviour analysis entity vs its history and peers Posture Continuous monitoring running system vs approved baseline Name the reference before choosing the practice each one may only conclude about the reference it compares against

Cheat sheet

  • Name what each practice compares against before choosing one
  • Threat modelling is a cycle you re-enter on every design change
  • STRIDE sweeps every component through six threat categories
  • Treat generated threats as candidates until they clear acceptance criteria
  • Modelling an AI system changes the catalogue, not the method
  • UEBA compares an entity against three references at once
  • A peer group is only as good as the directory it came from
  • Two scores in one product can answer two different questions
  • Resolve identifiers to one entity before you score anything
  • Capture a score's evidence at the moment the score is generated
  • A behaviour score about a person opens a process and never closes one
  • Anomalous behaviour splits into risky, unexpected and unintentional
  • An insider threat programme is cross-discipline, not a product
  • Monitoring accounts for atypical usage carries a privacy assessment
  • Continuous means a frequency chosen from risk, not constantly
  • Sort a monitoring requirement into effectiveness, change or compliance
  • CA-7 asks for two frequencies, not one
  • Continuous monitoring runs on three tiers and aggregates upward
  • Configuration drift is a comparison of two states, not an event
  • Hunting targets what your existing controls would have missed
  • State the hypothesis and its scope before opening a query window
  • A model cannot tell absence of the adversary from absence of data
  • Every hunt ends in a new detection or a recorded negative
  • An entity you do not collect from has a perfect record
  • Measure coverage, conversion and freshness, not activity

Unlock with Premium — includes all practice exams and the complete study guide.

Also tested in

References

  1. CompTIA SecAI+ (CY0-001) certification
  2. Threat Modeling Cheat Sheet
  3. Threats — Microsoft Threat Modeling Tool
  4. LLM09:2025 Misinformation (OWASP Top 10 for LLM Applications) Whitepaper
  5. Security and Privacy Controls for Information Systems and Organizations (NIST SP 800-53 Rev. 5) Whitepaper
  6. Guidelines for secure AI system development: secure design Whitepaper
  7. Advanced threat detection with User and Entity Behavior Analytics (UEBA) in Microsoft Sentinel
  8. CompTIA Security+ (SY0-701) exam objectives
  9. Information Security Continuous Monitoring (ISCM) for Federal Information Systems and Organizations (NIST SP 800-137) Whitepaper
  10. Information security continuous monitoring (ISCM) glossary entry
  11. Guide for Security-Focused Configuration Management of Information Systems (NIST SP 800-128) Whitepaper
  12. MITRE ATT&CK